CMMC 3.12.1 (Security Control Assessment): Evidence Examples & What Assessors Actually Check

    Control: NIST SP 800-171 Rev. 2 §3.12.1 · CMMC Practice: CA.L2-3.12.1 · Updated June 2026

    Plain-English answer

    3.12.1 requires you to periodically assess your security controls to determine whether they're effective in their application. Two parts: define how often you assess, and actually do it — verifying controls work as intended. This is your own internal assessment cycle, distinct from the formal C3PAO certification.

    Who this applies to

    Every organization seeking CMMC Level 2 for a CUI environment.

    Why it matters

    Controls drift. A periodic effectiveness assessment is how you catch a control that quietly stopped working before an assessor — or an attacker — does. It carries a weighted SPRS deduction if unmet (verify the exact value against the DoD Assessment Methodology).

    Control lineage

    • CMMC Practice: CA.L2-3.12.1
    • NIST 800-171 Rev. 2: §3.12.1 — periodically assess the security controls in organizational systems to determine if the controls are effective in their application.
    • NIST 800-171A objectives: [a] the frequency of security control assessments is defined; [b] security controls are assessed with the defined frequency to determine if the controls are effective in their application.

    What the assessor will EXAMINE

    • A policy/plan defining the assessment frequency (e.g., annual control self-assessment).
    • Completed assessment results/reports dated on that cadence, covering the in-scope controls.
    • Findings from the assessments flowing into the POA&M.
    • SSP narrative for 3.12.1 and linkage to the assessment method.

    What the assessor will INTERVIEW & TEST

    • Interview: "How often do you assess your controls, what method do you use, and what did the last one find?" — point to the defined cadence and the latest report.
    • Test: Confirm the most recent assessment actually happened on schedule and covered the in-scope controls.
    • Test: Verify findings led to corrective action (POA&M items), not just a filed report.

    Evidence examples (produce these)

    • Assessment policy/plan stating the frequency and method.
    • Dated control-assessment reports (e.g., the annual self-assessment against all 110 requirements).
    • Evidence findings were tracked to closure or onto the POA&M.
    • SSP section 3.12.1 referencing the above.

    Common failure patterns

    • Controls implemented but never periodically assessed — objective [b] fails.
    • No defined frequency, so assessments are ad hoc — objective [a] fails.
    • An assessment was run once at setup and never repeated.
    • Assessment findings never become corrective actions.

    SPRS impact & POA&M

    SPRS: 3.12.1 carries a weighted deduction (verify the exact value). POA&M: confirm 3.12.1's POA&M eligibility against current CMMC rules before assuming it can be deferred.

    Assessor-ready summary

    You're good on 3.12.1 when an assessment frequency is defined; control-effectiveness assessments run on that cadence and cover the in-scope controls; findings drive corrective action and POA&M items; and the SSP matches the practice.

    When did you last verify your controls actually work — not just exist? Book a DIBCAC-style readiness assessment →

    Related: 3.12.4 System Security Plan · 3.12.2 POA&M · All control pages

    Athena prepares organizations for CMMC Level 2; certification rests with C3PAOs/DIBCAC. Verify all control facts against NIST SP 800-171 Rev. 2, NIST SP 800-171A, and current CMMC rules.